LOW 3.7 PyPI
Flask-AppBuilder Observable Response Discrepancy
GHSA-p8q5-cvwx-wvwp · CVE-2025-24023 · PYSEC-2025-15
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non authenticated user to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.
Patches
Upgrade to flask-appbuilder>=4.5.3
Workarounds
Downgrade werkzeug to <3.0.0
References
Are there any links users can visit to find out more?
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes